Earlier quoted context omitted.
I think its a perfect analogy. >because the Linux project isn't dedicated to auditing the Linux project. Huh? Code Review? Testing? The entire point of open source especially w.r.t security is to have millions of eyes on the source. Heck with the entire world being able to audit and review the source code, people still find bugs that were introduced decades ago. >It's like calling a home security system pointless if…
>Heck with the entire world being able to audit and review the source code That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it. >I simply asked a commentor to show the work they've done And it was a dumb question. An auditing company that failed to…
Linux is developed almost exclusively by people who get paid for their work. Billions of dollars of real money has been poured by IBM, Intel, RH, etc. You are thoroughly confused my friend. Lets stick with the original point.
> An auditing company that failed to detect massive fraud either willfully ignored it to sellout or was too incompetent to recognize it.
So explain how they audited the firm, explain which data they had access to and how they were incompetent
You can't define your way out of providing evidence. An auditor does X. They couldn't do X, therefore they were incompetent. That schoolyard logic doesn't work. People will ask you to backup your opinion. Its completely fine to say I don't know...